Access data sources across domains - Internet Zone | MSCT Windows Server 2025 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Accounts: Limit local account use of blank passwords to console logon only - LimitBlankPasswordUse | MSCT Windows Server 2025 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Allow indexing of encrypted files - AllowIndexingEncryptedStoresOrItems | MSCT Windows Server 2025 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Allow only approved domains to use ActiveX controls without prompt - Internet Zone | MSCT Windows Server 2025 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows Server 2025 DC v1.0.0 | Windows | ACCESS CONTROL |
Allow VBScript to run in Internet Explorer - Internet Zone | MSCT Windows Server 2025 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Audit Account Lockout | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit Authentication Policy Change | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit Credential Validation | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit insecure guest logon - LanmanServer AuditInsecureGuestLogon | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit Kerberos Service Ticket Operations | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit Security Group Management | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit Security System Extension | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit System Integrity | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit User Account Management | MSCT Windows Server 2025 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Boot-Start Driver Initialization Policy - DriverLoadPolicy | MSCT Windows Server 2025 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
Configure Attack Surface Reduction rules - e6db77e5-3df2-4cf1-b95a-636979351e5b | MSCT Windows Server 2025 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
Configure detection for potentially unwanted applications | MSCT Windows Server 2025 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Configure enhanced anti-spoofing - EnhancedAntiSpoofing | MSCT Windows Server 2025 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Configure hash algorithms for certificate logon - KDC PKINITSHA1 | MSCT Windows Server 2025 DC v1.0.0 | Windows | |
Configure hash algorithms for certificate logon - Kerberos PKInitSHA256 | MSCT Windows Server 2025 DC v1.0.0 | Windows | |
Configure Windows Defender SmartScreen - EnableSmartScreen | MSCT Windows Server 2025 DC v1.0.0 | Windows | ACCESS CONTROL |
Manage auditing and security log | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
NetBT NodeType configuration | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Network access: Do not allow anonymous enumeration of SAM accounts | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Network access: Restrict anonymous access to Named Pipes and Shares | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Password must meet complexity requirements | MSCT Windows Server v20H2 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Perform volume maintenance tasks | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Prevent bypassing SmartScreen Filter warnings | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
Prevent ignoring certificate errors | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Remote host allows delegation of non-exportable credentials | MSCT Windows Server v20H2 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Run .NET Framework-reliant components not signed with Authenticode - Internet Zone | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Run .NET Framework-reliant components signed with Authenticode - Internet Zone | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Security Zones: Do not allow users to add/delete sites | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Select cloud protection level | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
Set client connection encryption level | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Sign-in and lock last interactive user automatically after a restart | MSCT Windows Server v20H2 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Specify use of ActiveX Installer Service for installation of ActiveX controls | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Take ownership of files or other objects | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Turn off Crash Detection | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Turn off the Security Settings Check feature | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Turn on Cross-Site Scripting Filter - Internet Zone | MSCT Windows Server v20H2 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Turn on Enhanced Protected Mode | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Turn on PowerShell Script Block Logging - EnableScriptBlockLogging | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Turn On Virtualization Based Security - HVCIMATRequired | MSCT Windows Server v20H2 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
User Account Control: Only elevate UIAccess applications that are installed in secure locations | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
User Account Control: Run all administrators in Admin Approval Mode | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |